Iranian state-backed threat group APT42, also known as Charming Kitten and Educated Manticore, has launched a sophisticated cyberespionage campaign dubbed SpearSpecter, targeting high-profile defense and government organizations as well as their officials and family members. The campaign leverages weeks-long social engineering lures via WhatsApp to gain initial access, followed by credential theft through redirection to fake meeting pages. For long-term persistence, the attackers deploy a fileless PowerShell-based backdoor named TAMECAT, which enables command execution, reconnaissance, file harvesting, and browser data exfiltration. The campaign demonstrates advanced operational security and agility, with infrastructure designed for prolonged espionage against high-value targets.
Researchers note that TAMECAT's capabilities allow attackers to maintain stealth and flexibility, executing further PowerShell code and adapting their operations based on their objectives. The Israel National Digital Agency highlighted that these attacks are distinct from previous APT42 campaigns, reflecting a continuous evolution in tactics. The campaign's focus on defense and government entities underscores the persistent threat posed by Iranian cyber operations to critical infrastructure and sensitive sectors worldwide.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Subsequent reporting said the Iran-linked SpearSpecter operation used weeks-long social-engineering lures delivered via WhatsApp to target defense-related entities. It also reiterated the use of the fileless TAMECAT backdoor in the campaign.
INDA said SpearSpecter intrusions can range from credential theft through fake meeting-page redirects to long-term persistence using the PowerShell-based TAMECAT backdoor. The agency described TAMECAT as capable of executing additional PowerShell code, reconnaissance, file harvesting, and browser-data exfiltration, and characterized the infrastructure as stealthy and operationally mature.
Israel’s National Digital Agency reported a new cyberespionage campaign dubbed SpearSpecter and attributed it to the Iranian state-backed actor APT42. The campaign targets high-profile defense and government organizations and officials, as well as some family members of those officials.
A June 2025 campaign attributed to APT42 was reported by Check Point and involved two APT42 subgroups. Later reporting said the SpearSpecter activity differed from this earlier operation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.